Reporting

Is it possible to define different source email addresses for different scheduled reports/alerts?

marlog
Explorer

Looks like it is possible to set "Send email as" to a custom email address that would appear in the From field in scheduled alerts/reports. However, this would take effect across the board and we have different teams that would like to use their group emails for their alerts/reports. Is it possible to set different "Send email as" to different alerts/reports?

0 Karma

somesoni2
Revered Legend

I believe you can set the action.email.from = for each saved search/alert level. See if that's available for update from Splunk Web UI in advanced edit on Searches, reports and alerts.

0 Karma

elliotproebstel
Champion

Sure, if you use the sendemail command inline on the search. For example:

index=myindex | head 10 | sendemail to=recipient@test.com from=sender@test.com

0 Karma

elliotproebstel
Champion

BTW, you can read about the whole list of options available with the sendemail command here:
http://docs.splunk.com/Documentation/Splunk/7.0.0/SearchReference/Sendemail

0 Karma

marlog
Explorer

Thank you very much for your suggestion. However, I am looking at "Schedule PDF Delivery" where the Dashboard can be sent as a PDF attachment to an email. And also regular scheduled Alerts.

0 Karma

elliotproebstel
Champion

Ahh, in that case, then I think @somesoni2 is on the right track for helping you in his comment above!

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...